reviewing-pull-requests

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core GitHub review workflow is purpose-aligned and mostly benign, but the skill is high-risk in operation because it processes untrusted PR/issue content while empowered to take write actions, creating indirect prompt-injection risk. The unverified `linear-cli` reference also weakens install/execution trust, though there is no direct evidence of malware or credential theft.

Confidence: 88%Severity: 64%
Audit Metadata
Analyzed At
Mar 21, 2026, 07:20 PM
Package URL
pkg:socket/skills-sh/trevors%2Fdot-claude%2Freviewing-pull-requests%2F@3eeda304adceb6efa26fe48559ed4af7cc4ea2fd